Cylance Threat: File is waived · cylance_threats.file_status = waived
Description
Cylance Threat: File $(cylance_threats.file_path) is waived
Query · wazuh
field cylance_threats.file_status="waived"
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=cylance_threats -
87051Cylance Threat: File is waived · cylance_threats.file_status = waived refinement level 3 this rulefield cylance_threats.file_status="waived"
Rule dependencies
Depends on
-
composes · Wazuh if_sid
87050